Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps team is deploying a multi-tier application on AWS. The application must comply with PCI DSS. Which combination of services should be used to encrypt data in transit between the web tier and the application tier?

⚠ Common exam trap

The trap is picking KMS or CloudHSM for 'encryption' — candidates forget that KMS encrypts data at rest and CloudHSM stores keys, while encryption in transit requires TLS, which on AWS means ACM plus a load balancer that terminates and re-encrypts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Certificate Manager (ACM) and Application Load Balancer (ALB)

AWS Certificate Manager (ACM) provisions and manages the TLS certificates, and an Application Load Balancer (ALB) terminates TLS and re-encrypts traffic to backend targets, providing encryption in transit between the web tier and the application tier. This combination is the standard AWS pattern for PCI DSS-compliant in-transit encryption on a multi-tier application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Certificate Manager (ACM) and Application Load Balancer (ALB)

    Why this is correct

    ACM issues and automatically renews public or private TLS certificates that integrate natively with an ALB's HTTPS listener, allowing the ALB to terminate TLS and encrypt traffic between the client and load balancer. For multi-tier architectures, the ALB can front each layer (e.g., web and application), providing encrypted inter-tier communication without manual certificate deployment or key management. This approach leverages AWS-managed distribution, per-listener policies, and SNI support, directly addressing the requirement for in-transit encryption.

  • ✗

    AWS CloudHSM and Classic Load Balancer

    Why it's wrong here

    CloudHSM provides tamper-resistant hardware security modules for storing and using cryptographic keys, but it does not itself encrypt network traffic; you would need separate TLS termination or IPsec mechanisms. Classic Load Balancer supports only a single SSL certificate per listener, lacks SNI, and does not integrate with ACM for automated renewal, making it impractical for encrypting traffic between multiple microservice tiers. The combination addresses neither the network encryption requirement nor the operational need for centralized TLS management.

  • ✗

    AWS KMS and VPC Peering

    Why it's wrong here

    AWS KMS is a managed key management service that generates and controls symmetric/asymmetric encryption keys used primarily for at-rest data encryption, not for encrypting traffic on the network wire. VPC Peering simply creates a private Layer-3 IP route between two VPCs; it does not introduce any encryption, so any packets traversing the peering connection remain in plaintext. Even though KMS keys could theoretically be used by other services to establish TLS, pairing KMS with VPC Peering does not configure any encryption between tiers, leaving the transmission vulnerable.

  • ✗

    AWS WAF and Amazon CloudFront

    Why it's wrong here

    AWS WAF is a web application firewall that inspects and filters HTTP/S requests for threats like SQL injection or cross-site scripting; it has no capability to encrypt data, and applying it to an ALB or CloudFront does not change the encryption status of traffic between internal tiers. Amazon CloudFront is a content delivery network designed to distribute content to end users at edge locations, not to securely route traffic between application tiers inside a VPC. While CloudFront can terminate HTTPS at the edge, it is not a suitable mechanism for encrypting internal service-to-service communication, which is what the multi-tier deployment actually requires.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.